GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

LULA Token on BSC Chain Suspected of Attack, Losses Approximately $578,100

According to TenArmorAlert monitoring, its system detected a suspicious attack involving the LULA token on the BSC chain, resulting in losses of approximately $578,100.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

Robinhood CEO's X Account Hacked, Fake Meme Coin Information Deleted

According to The Block, Robinhood CEO Vlad Tenev's X account was hacked at approximately 17:24 UTC on July 23. Hackers posted claiming to launch "Vladhood ($VLAD)" as the "official mascot of Robinhood Chain," and attached a contract address. The Robinhood Chain blockchain explorer has labeled the token as a "potential scam," and the token has generated approximately 1,868 transactions since deployment. Robinhood officially confirmed later that the account was compromised, the relevant posts have been deleted, and the company is working with the X platform to restore account access.

Taiko: Attack Resulted from Off-Chain Signature Key Leak and Verification Process Gap

Odaily News: Ethereum Layer 2 network Taiko released a post-mortem of the June 21 security incident, stating that the attack resulted from an off-chain signature key leak and a verification process gap. The attacker exploited these to forge proofs and bypass the Prover whitelist, rather than breaking ZK cryptography or smart contracts. The attacker stole approximately $1.75 million from cross-chain bridges and Vaults, but over $11 million in assets were protected, and no user funds were lost. Taiko has fixed the vulnerability, restored the pre-attack state, and resumed operation on July 2; an OpenZeppelin audit confirmed the fixes with no high, medium, or low-risk vulnerabilities identified. The official statement also indicated that the Unzen upgrade, scheduled for August 6, will require ZK proofs for every block to further enhance network security.

VerusCoin Ethereum Cross-Chain Bridge Attacked, Approximately $7.53 Million Transferred Out

According to CertiK Alert monitoring, a security incident occurred on VerusCoin's Ethereum cross-chain bridge, with approximately $7.53 million in assets transferred out. Preliminary analysis indicates that this issue may be related to the cross-chain bridge failing to sufficiently verify whether the Verus chain-side input supports the paid amount, similar to an incident that occurred in May this year.

B² Network suspected of being exploited, attacker transfers 8.591 million B2

: According to on-chain detective Specter’s monitoring, B² Network may have suffered a vulnerability exploit on BNB Chain. The attacker transferred 8.591 million B2, worth $3.86 million, and exchanged them for 5,409 WBNB, worth $3.11 million. The funds were then bridged to Ethereum, and are currently being transferred to Zcash via NEAR Intents. The addresses used for the theft are 0xEc443f7D79835B464FBEAC798d3f92B62d6Ff433 and 0xf977427Ec8e583C55D413061FC205BCD57e8Bf6D.

B² Network Suffers Hacker Attack, Losses Approximately $3.86 Million

According to on-chain analyst Specter, B² Network on BNB Chain suffered a hack, resulting in a loss of approximately 8.591 million B2 tokens (approximately $3.86 million). The attacker swapped them for 5409 WBNB (approximately $3.11 million) and bridged to Ethereum, and is currently transferring the funds to Zcash via NEAR Intents.

GoPlus and Salus Officially Join TermiX Agent.family, Launching On-Chain Security Audit Provider Agent Services

: BNB Chain Agent commercial clearing layer TermiX announced that Web3 security infrastructure GoPlus and smart contract security auditing firm Salus have officially become Provider Agents on the Agent.family platform. They have launched two production-grade security audit services, promoting the autonomous invocation and settlement of "security capability as a service" for AI Agents in on-chain commercial scenarios.GoPlus has packaged its verified token contract deep scanning capability as a standard Provider Agent service. DeepScan conducts comprehensive security checks on token contracts, identifying risk patterns such as Rug Pulls, honeypot scams, contract permission abuse, and trading restrictions, and generates structured audit reports.Salus has launched smart contract auditing and penetration testing services, encompassing formal verification, fuzz testing, machine learning-based vulnerability detection, and manual expert auditing. It covers high-risk vulnerability categories such as reentrancy attacks, access control issues, integer overflows, and DoS attacks. Salus, a seed-stage investment from Binance Labs, is a core security partner within the BNB Chain ecosystem.

Balance Coin Plunges Over 99%, 42DAO Allegedly Hit by $915,000 Attack

Odaily Planet Daily reported that the algorithmic stablecoin Balance Coin dropped from $0.9954 to $0.001358, a decline of over 99%. The stablecoin is the native algorithmic stablecoin of the Balance Protocol, designed to maintain a peg to the US dollar. Blockchain security firm PeckShield stated that the depegging occurred following an exploit of the decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token, resulting in a $915,000 loss. TenArmor reported detecting suspicious attacks involving GemJoin and 42DAO on the BNB Chain.

Midnight:Multiple Exchanges Including Binance Freeze Funds Involved in Cross-Chain Bridge Attack

the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.

Pons responds to front-end authorization vulnerability: Launchpad trading page lacks Multicall3 functionality, only $0.66 worth of NOXA affected

Robinhood Chain launchpad Pons has officially responded to earlier reports about a token authorization vulnerability in its front end, stating that the Pons launchpad trading page does not have any Multicall3 functionality. The Multicall3 feature mentioned in the tweet originated from the previous Debank Chain old version bridge and was released before the Pons launchpad, thus it does not affect launchpad users. It is currently confirmed that only 0.60 NOXA tokens, valued at approximately $0.66, are affected.As a security precaution, Pons recommends that users who previously used the old version bridge revoke token authorizations via revoke.cash. The team is currently working with audit firms to investigate potential risks and has stated that Pons' front-end services will be restored after confirming the absence of any actual vulnerabilities.

Token Pocket Chief Business Officer: Robinhood Founder's Seed Phrase Leaked During Live Stream, Address Now Frozen

Michael, Chief Business Officer of Token Pocket, stated on platform X that Robinhood founder's seed phrase was leaked during a live stream. After gaining control of the address, the hacker used it and associated addresses to heavily purchase the Meme token $1, prompting thousands of investors to follow suit. In a short time, the token's market cap quickly surged from approximately $500,000 to $14 million.Subsequently, the price of the $1 token dropped sharply, with two-hour trading volume reaching around $20 million. After the address was frozen, the hacker quickly moved to the BNB Chain, using the address and its associated addresses to issue a new token. They created trading activity through tactics like wash trading, ultimately dumping the tokens for profit.Currently, Robinhood's RPC has frozen the address, and the node does not allow transactions originating from this address to be packaged, making transfers, purchases, or sales impossible.

TAC Responds to Sharp Price Drop: No Attack, No Internal Sell-Off, Decline Triggered by Chain Reaction of Contract Liquidations

According to official sources, TAC issued a statement regarding the significant price drop in the past 24 hours, stating that the protocol was not attacked, on-chain assets are secure, and the system is operating normally; the team and early investors did not participate in the sell-off, relevant tokens remain in the lock-up and vesting period, and there is no possibility of unlocking at this stage.

BNB Chain Launches New Layer 1 for Agent Trading, Targeting 2027 Mainnet Launch

According to The Block, BNB Chain is building a new Layer 1 blockchain designed specifically for agent trading, targeting transaction pre-confirmation in under 50 milliseconds, and suppressing MEV behaviors such as sandwich attacks by eliminating the public mempool (adopting the TxStream mechanism). The new chain will also reserve block space for oracles, liquidations, and cross-chain bridges via PriorityLane, with a designed throughput target exceeding 100,000 TPS, and supporting sub-second block finality. This chain will become the fourth chain in the BNB Chain ecosystem, connected to BNB Smart Chain via a native bridge, with BSC serving as the settlement hub. The testnet is planned to launch at the end of 2026, and the mainnet is expected to deploy in early 2027.

BNB Chain plans to launch a new Layer 1 blockchain, with mainnet expected to go live in 2027

BNB Chain is developing a new Layer 1 blockchain designed for Agentic Trading, releasing the first detailed architectural information after months of research and development. According to BNB Chain's disclosed technical roadmap for the second half of 2026, the new chain will run in parallel with the existing BNB Chain ecosystem, targeting transaction preconfirmation times of less than 50 milliseconds. The goal is to deliver an execution experience close to that of centralized exchanges (CEX) while retaining the advantages of on-chain self-custody and transparency.In terms of technical architecture, the new chain will remove the traditional public mempool and introduce a transaction transmission mechanism called "TxStream," which directly sends transactions to block producers to reduce latency and minimize MEV extraction behaviors such as sandwich attacks. (The Block)

SecondFi: On-Chain Recovery Plan More Complex Than Expected, Recovery May Exceed Two Weeks

: Cardano wallet service provider SecondFi has released an update on the security incident recovery progress, stating that EMURGO has established an asset recovery fund to return assets to users affected by the attack.SecondFi stated that emergency measures have been taken to protect and restore access to some assets. The team is currently discussing appropriate custody mechanisms with Intersect to ensure the safe return of assets to users.Furthermore, SecondFi is collaborating with a Cardano community-led working group to advance the on-chain recovery plan. Due to the recovery plan being more complex than initially expected, the overall recovery time may exceed the previously estimated two weeks.

Base Releases Block Production Outage Analysis Report: Sequencer Bug Causes Brief On-Chain Downtime, Protocol Stress Testing to Be Strengthened

Base has officially released an analysis report on the block production outage, disclosing that the Base mainnet experienced two block production interruptions on June 25 and 26, lasting 116 minutes and 20 minutes respectively. On-chain asset security was unaffected, and funds remained safe at all times. The root cause was a vulnerability in the sequencer's block construction logic: after a transaction execution failure, the old journal state was not properly cleared, causing subsequent legitimate transactions to encounter gas calculation errors during execution, thereby generating invalid state transition blocks and halting block production on the entire L2 chain.Base stated that the issue has been resolved through a patch, and will strengthen the protocol's fuzz testing and stress testing framework to identify potential malicious transaction paths, while optimizing monitoring and operational processes. Additionally, plans are in place to introduce a recovery mechanism to enhance rapid recovery capabilities in future similar events.

“Cordyceps” CI/CD Supply Chain Vulnerability Pattern Exposed, Affecting Code Repositories of Microsoft, Google, and Others

Cybersecurity firm Novee, in its latest research, revealed a CI/CD supply chain vulnerability pattern dubbed “Cordyceps,” primarily involving command injection, authentication logic flaws, artifact poisoning, and privilege escalation within GitHub Actions workflows. According to the report, unauthenticated users can exploit these vulnerabilities under specific conditions to hijack workflows, steal credentials, or gain control of code repositories.

HashKey Chain Japan Hackathon Countdown Begins: $12,000 USDT Total Prize Pool Invites Global Developers

HashKey Chain will host the “HashKey Chain Horizon” hackathon in Japan from June 18 to July 14. Built upon the foundation of building a compliant and secure Web3 ecosystem, this hackathon is open to developers, innovators, and Web3 enthusiasts worldwide. It features two challenge tracks focused on key areas within the HashKey Chain ecosystem.

Taiko Chain State Verification Mechanism Compromised, Users Urged to Immediately Withdraw Funds from Cross-Chain Bridges

Taiko stated on its X platform that it has confirmed its chain state verification mechanism has been compromised, and the security assumptions of all cross-chain bridges deployed on Taiko are no longer reliable.Taiko said it is coordinating with its security committee and ecosystem partners to control the situation, suspending affected systems, and taking technical and legal actions. Taiko strongly advises all users to immediately withdraw funds from cross-chain bridges deployed on Taiko.Additionally, Taiko has made an urgent request for all centralized exchanges to suspend TAIKO token deposit services until further official notice. Previously, Taiko's ERC20 Vault was attacked, resulting in losses exceeding $1 million.